mdrabble Posted September 29 Posted September 29 just over 2 years ago I managed to persuade SLT to drop student wifi (BYOD) access for the following reasons. Cyber Security issues/concerns Web Filtering - either blocked due not installing SSL Cert or the use of VPN to bypass it. Now, there could be rumblings of the 6th Form team asking for it to be reinstated. How many other schools with 6th Form allow Student BYOD What Firewall/Filtering to you have and what APs? Did have Smoothwall and Unfi NanoHD Aps and now have a Fortigate with Unifi U7 APs. Any info welcome. Cheers 1
3s-gtech Posted September 29 Posted September 29 We have it, it's actually necessary due to the way we issue them laptops that aren't on our domain. Uses RADIUS with their normal logon, but it does not pop out on our range and it's on a separate VLAN I think. Filtering managed further up the chain by the firewall (LEA managed). Cisco APs (AX). 1
Primus Posted September 29 Posted September 29 Think carefully about how you are going to effectively filter and monitor devices using your connection which are not managed by you - in my previous role we removed BYOD entirely because of this. 1
ThomL Posted September 29 Posted September 29 We have FortiGate firewall, Smoothwall filtering, Cisco Meraki Access points, radius authentication with AD credentials. Student authenticate with their school account to the SSID, Meraki places the traffic on a specific 6th Form BYOD vlan. Vlan is location in the smoothwall to fine tune filtering if required, intervlan routing is handled by the firewalls which block everything between internal vlans and allow only specific ports to connect to the wan from the 6th form byod vlan. We do need to assist students wishing to join the network as they require the SSL CA cert installing, but this is manageable with the number of students and techs we currently have; 6th form students have a suite of domain joined computers they can use for study sessions/outside of lessons which lifts some of the pressure for byod. 2
synaesthesia Posted September 29 Posted September 29 (edited) Currently you might have to lock it down so it's only certain devices, which some might deem unfair. You can't offer BYOD to anyone using iPhones or iPads with mobile connectivity and remain KCSIE compliant. For this purpose we're looking at removing it entirely from 6th form. Edited September 29 by synaesthesia 1
mdrabble Posted September 29 Author Posted September 29 Before I removed it, they were in a isolated VLAN but due to not really know what was connected, I played the Cyber Security and Safeguarding cards which worked - as I was backe by the DSL and I'm hoping he is still on my side!
ThomL Posted September 30 Posted September 30 17 hours ago, synaesthesia said: Currently you might have to lock it down so it's only certain devices, which some might deem unfair. You can't offer BYOD to anyone using iPhones or iPads with mobile connectivity and remain KCSIE compliant. For this purpose we're looking at removing it entirely from 6th form. Can you expand on this so I can review and start discussions here please?
synaesthesia Posted September 30 Posted September 30 1 hour ago, ThomL said: Can you expand on this so I can review and start discussions here please? Sure - see In a nutshell, where mobile data is available should a device not be able to reach a website (in our case due to filtering) it will use other methods to get to that site, effectively loading it via mobile data even though wifi is available. How this is reported on filtering systems is yet to be seen - the current assumption would appear to be it shows as blocked, but in reality the user is browsing those sites apparently still connected via WiFi. My understanding may be flawed however and there's been precious little information other than this and a couple of news articles. It may be that we just "suck it up" but in my black and white mind I can't see how this could be usable.
Roberto Posted September 30 Posted September 30 (edited) This is obviously knocking on a bit since I was in education, but we implemented Eduroam with all the implications around RADIUS + Cert Auth for device and user identification. This allowed us to provide appropriate filtering on our connection as our WiFi and Firewall/Filtering system shared the same RADIUS identity. Users only had use of the wifi to get access to whatever services we offered externally (which even then, were considerable due to stuff being in the cloud). This made visits by 6th formers to unis, and visits to us by uni people quite painless to support which was a nice bonus. Now we were a 6th form college which made it easier to do this of course, but it should be possible to set up Eduroam wifi, and only make it available to staff/6th formers. Now I've said all that, the points about KCSIE and mobile devices fetching sites however they can are very well made. I might be tempted to steer well clear of anything that might create ambiguity about whether your school allowed browsing of anything questionable, these days. The easiest way to win an argument remains avoiding having it in the first place. Edited September 30 by Roberto
EBrooke Posted October 1 Posted October 1 Another vote for eduroam here. We've had very good uptake on it and the benefits to staff and students are very clear. Personally I find that not providing any form of BYOD pushes students towards using their mobile data which may not be filtered appropriately. For cyber security concerns, would you be able to have the BYOD network's gateway on a firewall in an untrusted zone?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now